CVE List

Id CVE No. Status Description Phase Votes Comments Actions
975  CVE-1999-0995  Entry  Windows NT Local Security Authority (LSA) allows remote attackers to cause a denial of service via malformed arguments to the LsaLookupSids function which looks up the SID, aka "Malformed Security Identifier Request."        View
554  CVE-1999-0570  Candidate  Windows NT is not using a password filter utility, e.g. PASSFILT.DLL.  Proposed (19990728)  ACCEPT(1) Northcutt | MODIFY(1) Frech | NOOP(2) Baker, Christey | REJECT(1) Wall  Northcutt> Here we are crossing into the best practices arena again. However since | passfilt does establish a measurable standard and since we aren"t the | ones defining the stanard, simply saying it should be employed I will | vote for this. | Frech> XF:nt-passfilt-not-inst(1308) | XF:nt-passfilt-not-found(1309) | Christey> Consider MSKB:Q161990 and MSKB:Q151082  View
199  CVE-1999-0200  Candidate  Windows NT FTP server (WFTP) with the guest account enabled without a password allows an attacker to log into the FTP server using any username and password.  Modified (19991130-01)  ACCEPT(1) Baker | MODIFY(2) Frech, Shostack | NOOP(2) Northcutt, Wall | REJECT(1) Christey | REVIEWING(1) Levy  Shostack> WFTP is not sufficient; is this wu-, ws-, war-, or another? | Frech> Other have mentioned this before, but it may be WU-FTP. | POSSIBLY XF:ftp-exec; does this have to do with the Site Exec allowing root | access without anon FTP or a regular account? | POSSIBLY XF:wu-ftpd-exec;same as above conditions, but instead from a | non-anon FTP account and gain root privs. | Christey> added MSKB reference | CHANGE> [Christey changed vote from REVOTE to REJECT] | Christey> The MSKB article may have confused things even more. There | were reports of problems in a Windows-based FTP server called | WFTP (http://www.wftpd.com/) that is not a Microsft FTP | server. It"s best to just kill this candidate where it | stands and start fresh.  View
967  CVE-1999-0987  Entry  Windows NT does not properly download a system policy if the domain user logs into the domain with a space at the end of the domain name.        View
179  CVE-1999-0179  Entry  Windows NT crashes or locks up when a Samba client executes a "cd .." command on a file share.        View

Page 175 of 20943, showing 5 records out of 104715 total, starting on record 871, ending on 875

Actions